Malicious Calendar Invite (ICS Phishing) Attacks Surge

Malicious Calendar Invite Phishing Surges Over 30,000%

HIGH
September 18, 2026
3m read
PhishingMalware

Related Entities

Organizations

Sublime Security

Products & Tech

ScreenConnectGmail Microsoft Outlook

Full Report

Executive Summary

Security researchers at Sublime Security have identified an explosive growth in a phishing technique that leverages .ics calendar files to deliver malware. This method, dubbed "ICS phishing," has seen a projected 33,000% increase in volume between May and September 2026. Attackers use legitimate email services like Gmail to send malicious calendar invitations that often bypass traditional email filters. Because many email clients automatically add these events to the user's calendar, the victim is exposed to the malicious lure in both their inbox and their trusted calendar application, increasing the likelihood of interaction. The ultimate goal is to trick the user into clicking a link and installing a malicious Remote Monitoring and Management (RMM) tool, giving the attacker full control of the endpoint.


Threat Overview

ICS phishing is a highly effective social engineering tactic that abuses the trust users place in their calendar applications. The attack flow is simple but potent:

  1. Delivery: An attacker, using a free email account on a trusted provider like Gmail, sends a calendar invitation (.ics file) to the target.
  2. Bypass: Because the email originates from a reputable source (e.g., google.com), it often passes through email security gateways that are primarily focused on sender reputation.
  3. Placement: The user's email client (e.g., Microsoft Outlook) automatically processes the invitation and adds the event to their calendar, often without any user interaction.
  4. Lure: The user now sees the malicious event, which may contain an urgent subject line (e.g., "Invoice Overdue"), in two trusted places: their inbox and their calendar notifications.
  5. Compromise: The event description contains a link. If the user clicks it, they are directed to a site that prompts them to download and install what appears to be legitimate software, but is actually a malicious RMM tool like ScreenConnect (now ConnectWise Control).

Once the RMM tool is installed, attackers have persistent remote access to the device, which they can use to deploy secondary payloads like infostealers or ransomware (T1486 - Data Encrypted for Impact).

Impact Assessment

The surge in this attack vector poses a significant threat because it cleverly circumvents both technical controls and user expectations. Users are not accustomed to treating calendar invites with the same suspicion as email attachments. A successful attack leads to a full endpoint compromise, which can result in:

  • Theft of sensitive personal and corporate data.
  • Harvesting of credentials stored on the device.
  • Deployment of ransomware, leading to business disruption.
  • Use of the compromised device as a pivot point for further attacks on the network.

Cyber Observables — Hunting Hints

Security teams should hunt for the following patterns:

  • Email Logs: Search for incoming emails with .ics attachments from external, non-business email domains (e.g., gmail.com, yahoo.com).
  • Calendar Events: Look for calendar events created by external users that contain suspicious keywords (e.g., "invoice," "payment," "urgent") and shortened or non-standard URLs.
  • Network Traffic: Monitor for outbound connections from endpoints to known RMM service domains (e.g., screenconnect.com) that are not part of your organization's approved software list.
  • Endpoint Processes: Monitor for the execution of RMM tool installers or processes, especially if they were downloaded from a browser and initiated by a standard user.

Detection & Response

  • Email Gateway Configuration: Configure your email security gateway to specifically inspect the content of .ics files for malicious links and to apply stricter filtering to calendar invites from external free-mail providers. This is a form of D3-FA: File Analysis.
  • Disable Auto-Accept: Advise users or use GPO/MDM policies to disable the automatic processing and acceptance of calendar invitations in their email clients. This forces a manual review of each invite.
  • EDR/EPP: Ensure endpoint protection is configured to block the installation of unauthorized RMM software. Create detection rules for RMM tools that are not on your corporate allowlist.
  • User Training: This is critical. Educate users about the threat of ICS phishing. Teach them to be suspicious of any unexpected calendar invite, especially those that create a sense of urgency or come from an unknown sender.

Mitigation

  • Application Control: Use application control policies (D3-EAL: Executable Allowlisting) to prevent the execution of any RMM software that is not explicitly approved for use in your environment.
  • URL Filtering: Implement web filtering to block access to known malicious domains and file-sharing sites commonly used to host malware.
  • User Awareness: Reinforce to users that a calendar invite is just another potential delivery vector for a phishing attack and should be treated with the same level of caution as an email.
  • Principle of Least Privilege: Ensure that standard users do not have local administrator rights on their workstations, which would prevent them from installing most RMM software.

Timeline of Events

1
May 1, 2026
Start of the period analyzed by Sublime Security, marking the beginning of the surge in ICS phishing.
2
September 1, 2026
Sublime projects a 33,000% increase in ICS phishing attacks compared to May.
3
September 18, 2026
This article was published

MITRE ATT&CK Mitigations

Educating users to be suspicious of unexpected calendar invites is the most critical defense against this social engineering tactic.

Configuring email gateways to inspect .ics files for malicious links and to block known malicious URLs.

Mapped D3FEND Techniques:

Using application control to block the installation and execution of unauthorized RMM software.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

A key enabler of ICS phishing is the default behavior of email clients like Microsoft Outlook to automatically process calendar invitations and add them to the calendar. Organizations should use Group Policy Objects (GPO) for Outlook or Mobile Device Management (MDM) policies for mobile clients to change this setting. Configure clients to not automatically accept meeting requests. This forces the user to manually review and accept each invitation, creating a crucial moment of consideration. This simple configuration change disrupts the attacker's ability to plant their lure directly onto the user's trusted calendar application without scrutiny, significantly reducing the effectiveness of the attack.

Modern email security gateways must be configured to treat .ics files as a high-risk file type, similar to executables or scripts. Implement policies that force deep content inspection of all incoming .ics files. The security gateway should extract and analyze any URLs embedded within the calendar event's description or location fields. These URLs should be checked against reputation services and detonated in a sandbox environment to determine if they lead to a malicious download. By analyzing the content of the .ics file itself, organizations can detect and block the malicious invitation before it ever reaches the user's inbox or calendar.

Since this attack vector preys on user trust and social engineering, user training is a vital countermeasure. Security awareness programs must be updated to include specific modules on ICS phishing. Teach employees to be highly suspicious of calendar invitations from unknown external senders, especially those that create a sense of urgency (e.g., related to invoices, payments, or account issues). Instruct them to never click links within a calendar invite unless they have verified the sender's identity through a separate communication channel. Show them how to inspect the details of an invite and hover over links to see the true destination. This empowers users to become the last line of defense against this increasingly common threat.

Timeline of Events

1
May 1, 2026

Start of the period analyzed by Sublime Security, marking the beginning of the surge in ICS phishing.

2
September 1, 2026

Sublime projects a 33,000% increase in ICS phishing attacks compared to May.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

ICS-phishingsocial-engineeringRMMemail-securitycalendar-attack

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.